Holehe Field Guide
A practical companion guide to using Holehe well: how to read a report, when to retry, how to handle ambiguous results, and which third-party OSINT tools pair naturally with it. This isn't a separate product, it's a workflow page for getting more out of the Holehe you already use.
1. Reading a Holehe report
Every Holehe report has the same anatomy: a list of sites, each tagged Found, Not Found or Rate-limited, grouped into categories.
- Found, the site's public sign-up or password-recovery flow confirms an account exists for that email
- Not Found, the site returned a clear "no account" signal
- Rate-limited, the site blocked or throttled the probe; not a verdict
A clean report still has noise: treat rate-limited entries as "come back later," not as proof of absence.
2. Quick-look heuristics
A few patterns to recognise at a glance:
- Heavy social hits, no developer hits, likely a consumer account, not a technical one.
- Heavy developer hits (GitHub, GitLab, Stack Overflow, npm), likely a real engineer; expect a coherent username trail.
- Only one or two hits, the address is either niche-use or recently created. Cross-check with HaveIBeenPwned.
- Zero hits, frequently a disposable or relay address (HIDE/Apple/ DuckDuckGo Email Protection / SimpleLogin).
- Mostly shopping and music, light, personal use; the person is less likely to be technically inclined.
3. When to retry a scan
Rerun the same email a few hours later if:
- Several big platforms came back rate-limited
- You see an unusually low Found count for an old address
- You scanned during a peak hour on a known sensitive provider
Holehe rotates outbound IPs server-side, so a second run picks up a fresh egress and often resolves the rate-limited entries.
4. Companion OSINT tools
Holehe is one piece of a wider email-OSINT toolkit. The tools below answer the questions Holehe deliberately leaves alone.
Breach & reputation
- HaveIBeenPwned, known data breaches that include the address
- DeHashed / IntelX, broader leak coverage (paid)
- EmailRep.io, reputation score and abuse signals
Going deep on one account
- GHunt, public Google profile for a Gmail address
- EpieOS, web wrapper around several email-OSINT techniques
Username pivots
- Sherlock, classic handle-hunter across hundreds of sites
- Maigret, richer cousin of Sherlock with deeper metadata
- WhatsMyName, community ruleset, very fast
Domain & infrastructure
- whois / RDAP, registrant data for custom domains
- crt.sh, certificate transparency, useful for subdomain discovery
5. A sample workflow
- Holehe scan of the email → list of registered platforms.
- HaveIBeenPwned + EmailRep on the same email → breach and reputation context.
- If Gmail, run GHunt for the Google profile.
- Pick the strongest usernames from the Holehe report → Sherlock or Maigret.
- If custom domain → whois + crt.sh to map the infrastructure.
- Document with timestamps and source URLs.
Each tool feeds the next. Holehe is the spark that makes the rest of the chain useful.